CVE-2026-41091

high KEV
Published 2026-05-20 · Modified 2026-05-20
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
VIR risk
9.3

Description

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally.

CISA KEV

Vendor
Microsoft
Product
Defender
Due date
2026-06-03

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-41091 ; https://nvd.nist.gov/vuln/detail/CVE-2026-41091

vendor Authored 2026-05-27

Vendor advisory: secure@microsoft.com — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-41091

Mitigation details

Source: Microsoft Security Response Center · View original ↗ · proprietary-no-redistribution
Full prose not cached — VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftWindows Server 2012 R2
microsoftWindows Server 2012 R2 (Server Core installation)
microsoftMicrosoft Excel 2016 (32-bit edition)
microsoftMicrosoft Excel 2016 (64-bit edition)
microsoftMicrosoft Word 2016 (32-bit edition)
microsoftMicrosoft Word 2016 (64-bit edition)
microsoftMicrosoft Office 2016 (32-bit edition)
microsoftMicrosoft Office 2016 (64-bit edition)
microsoftWindows Server 2016
microsoftOffice Online Server
microsoftWindows 10 Version 1607 for 32-bit Systems
microsoftWindows 10 Version 1607 for x64-based Systems
microsoftWindows Server 2016 (Server Core installation)
microsoftMicrosoft SharePoint Enterprise Server 2016
microsoftMicrosoft SQL Server 2017 for x64-based Systems (GDR)
microsoftWindows 10 Version 1809 for 32-bit Systems
microsoftWindows 10 Version 1809 for x64-based Systems
microsoftWindows Server 2019
microsoftWindows Server 2019 (Server Core installation)
microsoftMicrosoft Office 2019 for 32-bit editions
microsoftMicrosoft Office 2019 for 64-bit editions
microsoftMicrosoft SharePoint Server 2019
microsoftVisual Studio Code
microsoftWindows Admin Center
microsoftMicrosoft .NET Framework 4.8 on Windows Server 2012
microsoftMicrosoft .NET Framework 4.8 on Windows Server 2012 R2
microsoftMicrosoft .NET Framework 4.8 on Windows Server 2016
microsoftMicrosoft .NET Framework 4.8 on Windows 10 Version 1607 for x64-based Systems

Exploits

Application impact

VendorProductVersionsFixed
windows microsoftmalware_protection_engine{"startIncluding":"1.1.26030.3008","endExcluding":"1.1.26040.8"}1.1.26040.8

References

CWEs

CWE-59

Verify integrity in audit chain (admin only). AS-IS.